CVE-2016-7460: XEE
The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7460?
CVE-2016-7460 is rated as moderate severity due to its potential to allow remote attackers to read arbitrary files or cause a denial of service.
How do I fix CVE-2016-7460?
To fix CVE-2016-7460, upgrade VMware vCenter Server to version 5.5 U3e or later, or version 6.0 U2a or later.
What systems are affected by CVE-2016-7460?
CVE-2016-7460 affects VMware vCenter Server 5.5 before U3e, 6.0 before U2a, and vRealize Automation 6.x before 6.2.5.
What is the impact of CVE-2016-7460?
The impact of CVE-2016-7460 could allow remote attackers to read sensitive files or disrupt services through a denial of service.
Is there a patch available for CVE-2016-7460?
Yes, VMware has released patches for CVE-2016-7460 in the updated versions of their vCenter Server and vRealize Automation software.